Overview
The Xero integration brings your accounting platform users into LowerPlane’s access reviews. Because Xero holds financial records, access to it is almost always in scope for an audit — reviewers need to show that only current, authorized employees can reach it. LowerPlane collects users and organization settings only. It does not read invoices, payments, contacts, bank transactions, or journals. The integration only ever reads data from Xero — it never creates or modifies anything in your accounting records.Prerequisites
A single connection covers every Xero organization you authorize. If your Xero login has access to several, select them all on the consent screen and each one is synced.
How to Connect
Authorize access
You are redirected to Xero and asked to sign in. The app requesting access appears as LowerPlane.Xero shows the access being requested:Organisation data (
accounting.settings.read)- View your organisation settings — this is what lets LowerPlane read the organization profile and the users who have access to it.
openid, profile, email)- View your name, email, and user profile — identifies you as the person who authorized the connection.
offline_access so it can refresh the connection without you re-authorizing every 30 minutes.LowerPlane deliberately does not request access to invoices, payments, contacts, bank transactions, or journals. No financial data leaves your Xero organization.
What LowerPlane Monitors
Users & Roles
User accounts, organization roles, and subscriber status for everyone with access to your Xero organization.
Organization Settings
The organization name, registered legal name, and country — enough to identify which legal entity each user account belongs to.
Automated Checks
Xero users are matched to your Personnel > People records by email address. That match drives the two access checks below, so keeping People current is what makes those results meaningful.| Check | Passes when |
|---|---|
| User should be identified | The Xero account has both an email address and a name |
| User access to critical system should be valid | The account belongs to a known person who has not been offboarded |
| Xero access should be removed for offboarded user | No terminated employee still has a Xero account |
What each failure means
User should be identified
User should be identified
A Xero account is missing an email address or a name, so it cannot be traced back to a named individual. This check looks only at the Xero account itself — it does not consult your People records.These accounts matter because no individual is accountable for them. If one is compromised, there is no owner to notify and no way to attribute activity.To resolve: set a first and last name on the account in Xero under Settings > Users, or remove the account if it is no longer needed.
An account whose email does not match anyone in People still passes this check. That case is reported by User access to critical system should be valid instead.
User access to critical system should be valid
User access to critical system should be valid
The account either belongs to nobody in your People records, or belongs to someone marked as terminated. Both mean access cannot be justified.To resolve: remove the account in Xero, or correct the person’s record in People if their status is wrong.
Xero access should be removed for offboarded user
Xero access should be removed for offboarded user
A person marked terminated in People still has an active Xero account. Xero removes users outright rather than disabling them, so any account visible to LowerPlane has live access right now.This is the highest-priority finding of the three — it means a departed employee can still reach your financial records.To resolve: remove the user in Xero under Settings > Users.
Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | Logical access to systems holding financial data is restricted to authorized personnel and revoked on termination |
| ISO 27001 | Access provisioning and deprovisioning controls are enforced for business applications |
Access Reviews
Xero users also appear in Personnel > Access Reviews alongside your other connected tools. Each authorized organization is registered as its own critical system —Xero (Test) and Xero (TEST 2), for example — so someone with access to two organizations is reviewed once per organization. Reviewers can confirm or flag access there as part of a periodic review campaign.
Access levels are normalized to a shared scale across every integration, so Xero roles such as
STANDARD and ADVISER are shown as custom. The exact Xero role is preserved on the collected evidence.Troubleshooting
All users fail the critical access check
All users fail the critical access check
The email addresses in Xero do not match your People records. Emails are matched exactly, in lowercase — confirm that the addresses in Personnel > People are the same ones used to sign in to Xero, not a work alias. A single mistyped character is enough to break the match.This affects User access to critical system should be valid. The identification check does not use People records, so it will keep passing.
An organization is missing from the results
An organization is missing from the results
Only organizations approved on the Xero consent screen are synced. Use Select another organisation there to add one, or reconnect and approve them all — the button confirms how many you are granting, for example “Continue with 2 organisations”.
The same person appears twice
The same person appears twice
Xero user accounts belong to a single organization, so someone with access to two organizations has two separate accounts. Both are listed and reviewed independently, each labelled with its organization. That is intentional — their role can differ between organizations, and access must be justified in each.
A user was removed in Xero but still shows in LowerPlane
A user was removed in Xero but still shows in LowerPlane
Removed users clear on the next sync. Trigger one manually from the integration page, or wait for the scheduled run.
The connection shows an error after working previously
The connection shows an error after working previously
Xero access tokens expire after 30 minutes and LowerPlane refreshes them automatically. If the refresh token itself is revoked — for example if the authorizing user’s Xero access is removed — the integration needs to be reconnected by a current admin.